Contact us

Innovation and Technology.

Information Security Office

The Information Security Office (ISO) is responsible for evaluating and responding to cyber risks to the City’s technical estate.

The ISO was created in 2013, consists of four people and is building the technical foundations necessary to perform enterprise security monitoring and response. The ISO works in a “Shared Services” model, evaluating and addressing risks and vulnerabilities within the City. This model creates a center of excellence within ISO and results in significant operational efficiencies and cost savings over department driven responses.

ISOs Key Objectives:

Develop and enforce an information security strategy, framework, polies and procedures that align City of Chicago business need, legislative and regulatory requirements and industry best practices

Assist City of Chicago IT projects and functional areas with the development of efficient processes that are required to meet requirements as defined by the Information Security Office and/or regulatory standards

Develop and support a NIST 800-30 and NIST 800-53 risk management framework to be used in information security solutions and asset prioritization

Develop a security awareness program to ensure that City of Chicago users understand their responsibility in protecting City of Chicago assets and information

Ensure that information security controls assist privacy efforts

Provide information security consulting and support to City of Chicago agencies in the area of compliance review, requirements definition, security risk assessment/measurement, security architecture and operational processes

Monitor and measure information security vulnerabilities and incidents and provide timely response to ensure confidentiality, integrity, availability and accountability of City of Chicago and its third-parties

Communicate the occurrence of significant security incidents, news, Information Security Office decisions and actions with City of Chicago